> Markdown version of [/jobs/ext/3027873-senior-incident-response-engineer](https://www.wearedevelopers.com/jobs/ext/3027873-senior-incident-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Incident Response Engineer - **Company:** Hays Specialist Recruitment LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Microsoft Azure, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Microsoft Security Essentials, Windows PowerShell, Security Information and Event Management, EndPointSecurity, Mitre Att&ck, Azure Security Center, SentinelOne Expertise - **Published:** September 22, 2026 - **Apply:** https://www.hays.com/job-detail/senior-incident-response-engineer--north-carolina_1186602 ## About the Role The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate's/applicant's qualifications, skills, and level of experience as well as the geographical location of the position. Applicants must be legally authorized to work in the United States. Sponsorship not available., * 5+ years of experience in Incident Response & Incident Management * Extensive hands-on experience with Microsoft security tools and platforms - Defender for Endpoint, Sentinel SIEM, SentinelOne etc. * Strong understanding of incident response lifecycle, NIST and MITRE ATT&CK frameworks. * Proficiency in log analysis, forensic investigation, and threat detection. * Excellent communication and documentation skills. * Ability to work independently and manage multiple incidents simultaneously. * Certifications such as GCFA, GCIH, CISSP, or Microsoft Certified: Security Operations Analyst Associate. * Experience with automation and scripting (PowerShell, Python). * Familiarity with cloud security (Azure, Microsoft 365). * Experience in regulated industries (e.g., finance, healthcare) is a plus. ## Description We are seeking a highly skilled and experienced Senior Incident Response Engineer to lead and manage the detection, investigation, and resolution of cybersecurity incidents. This role requires deep expertise in Microsoft security technologies and a strong understanding of incident response frameworks and processes. The ideal candidate will be a proactive problem solver, capable of working under pressure and collaborating across teams to protect organizational assets. You will also serve as the US Lead for incident response management. * Lead and coordinate incident response efforts across the organization, ensuring timely and effective resolution. * Utilize Microsoft security tools (e.g., Microsoft Defender for Endpoint, Microsoft * Sentinel, Microsoft Purview, Microsoft Defender XDR) to detect, analyze, and respond to threats. * Develop and maintain incident response playbooks, workflows, and escalation procedures. * Perform root cause analysis and post-incident reviews to identify gaps and improve security posture. * Collaborate with SOC analysts, threat hunters, and other stakeholders to enhance detection and response capabilities. * Provide mentorship and guidance to junior incident response team members. Stay current with emerging threats, vulnerabilities, and security technologies. * Participate in threat intelligence sharing and integrate findings into incident response strategies. * Ensure compliance with regulatory requirements and internal policies during incident handling. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)